Unexplained $4M memecoin drain hits EVM and Solana wallets

A roughly $4 million memecoin drain that touched both EVM and Solana wallets remains unresolved, even as on-chain traces show a broad set of transfers and subsequent routing through privacy tools. The central question is still how the signing access was obtained.
In a briefing on the incident, the drain was described as spanning multiple chains and moving across nine assets. Separate on-chain analysis cited in public posts pointed to wallet signatures being used to authorize transfers, rather than a simple token approval pull, but the available material does not establish the full entry point.
Transfers moved through both Solana and Ethereum paths
One on-chain analyst said the Solana side included valid wallet signatures and native SOL transfers, along with specific outflows of 1.43 million BP and other tokens to a receiving wallet identified as 69FnU8vszZSZF6DZCT6VHdsvm3DvvojDgbwqzHJ4cCFS. Those assets were then reported as being deposited into Privacy Cash, a privacy protocol used to obscure transaction trails.
The same analysis said 15 Ethereum transfers were also observed from a collection address, 0x427C4b37de0714821B09C4FC655a713AbbCfbA83, totaling 362 ETH. The tracing suggests the incident was not limited to one chain, but the available evidence does not show whether the EVM and Solana activity came from the same compromise path or separate ones.
Another public account, which said it had independently verified the transfers, described the flows as matching a signing compromise. It also said the unresolved issue is how the attacker gained signing access in the first place.
What the tracing does and does not show
The visible transaction data supports the conclusion that funds were moved through signed transfers and then pushed through privacy-focused services. It does not, on its own, identify the person or method behind the wallet access.
That distinction matters because wallet movement alone can point to compromise without explaining whether the exposure came from phishing, malware, a leaked seed phrase, a device breach, or another access path. None of those possibilities is confirmed in the material now available.
For now, the clearest facts are the scale, the cross-chain footprint and the post-drain routing. The cause remains open.






